<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How does Splunk forwarder handle data after uninstalling and reinstalling an app? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/How-does-Splunk-forwarder-handle-data-after-uninstalling-and/m-p/281969#M10694</link>
    <description>&lt;P&gt;The "file pointer" that tracks how far Splunk has read the input file is stored in the "fishbucket." The fishbucket is stored with the indexes. Unless you have deleted or reset the fishbucket in some way, the forwarder should pick up where it left off in processing the input.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Apr 2016 17:34:59 GMT</pubDate>
    <dc:creator>lguinn2</dc:creator>
    <dc:date>2016-04-12T17:34:59Z</dc:date>
    <item>
      <title>How does Splunk forwarder handle data after uninstalling and reinstalling an app?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-does-Splunk-forwarder-handle-data-after-uninstalling-and/m-p/281968#M10693</link>
      <description>&lt;P&gt;I have a bunch of forwarder machines that were inadvertently renamed recently. As a result, our forwarder manager no longer recognized the machines in the correct server class and apps were removed from the machine.&lt;/P&gt;

&lt;P&gt;One of the apps that was removed forwards data from a file. Since the app was uninstalled and later reinstalled, will the forwarder resend data from that file? Or will it still remember which line was last forwarded and just pick up where it left off?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2016 16:55:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-does-Splunk-forwarder-handle-data-after-uninstalling-and/m-p/281968#M10693</guid>
      <dc:creator>bruceclarke</dc:creator>
      <dc:date>2016-04-12T16:55:46Z</dc:date>
    </item>
    <item>
      <title>Re: How does Splunk forwarder handle data after uninstalling and reinstalling an app?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-does-Splunk-forwarder-handle-data-after-uninstalling-and/m-p/281969#M10694</link>
      <description>&lt;P&gt;The "file pointer" that tracks how far Splunk has read the input file is stored in the "fishbucket." The fishbucket is stored with the indexes. Unless you have deleted or reset the fishbucket in some way, the forwarder should pick up where it left off in processing the input.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2016 17:34:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-does-Splunk-forwarder-handle-data-after-uninstalling-and/m-p/281969#M10694</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2016-04-12T17:34:59Z</dc:date>
    </item>
  </channel>
</rss>

